CVE-2026-66422

Apache Tomcat: Servlet role references can bypass declarative role constraints

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


We have discovered 3,979 live websites that are affected by CVE-2026-66422.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains3,979 live websites (56% of Apache Tomcat install base)
Vulnerable Versions
  • from 7.0.97 through 7.0.109
  • from 8.5.46 through 8.5.100
  • from 9.0.25 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count190 versions ( 50% of all versions)


Common Weakness Enumeration

CWE-285 Improper Authorization



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • 4ra1n, pyn3rd and unam4 (finder)

Website Distribution by Country

Number of websites using CVE-2026-66422
United States1,454 websites



China634 websites
Germany277 websites
France127 websites
Italy119 websites
Brazil86 websites
Hong Kong84 websites
GB83 websites
India72 websites

Website Distribution by TLD

Number of websites using CVE-2026-66422
.com1,628 websites
.de197 websites
.edu190 websites
.net166 websites
.cn138 websites
.org129 websites
.it110 websites
.com.br105 websites
.fr55 websites
.com.cn55 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66422

Top websites that are affected by CVE-2026-66422. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
See full domain list

FAQ

CVE-2026-66422 is Improper Authorization in Apache Tomcat
A total of 3,979 websites have been identified as vulnerable to CVE-2026-66422, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-66422 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-66422.